ZeroHour
Security Affairspublished ()ingested @securityaffairs

Authentication Bypass Vulnerability found in Cisco Prime Home product

criticalVulnerabilityimportance 60CVE-2017-3791

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-3791
A vulnerability in the web-based GUI of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication and execute actions with admin

A vulnerability in the web-based GUI of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication and execute actions with administrator privileges. The vulnerability is due to a processing error in the role-based access control (RBAC) of URLs. An attacker could exploit this vulnerability by sending API commands via HTTP to a particular URL without prior authentication. An exploit could allow the attacker to perform any actions in Cisco Prime Home with administrator privileges. This vulnerability affects Cisco Prime Home versions from 6.3.0.0 to the first fixed release 6.5.0.1. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Cisco Bug IDs: CSCvb49837.

NVD description · AI analysis pending
10.04%
  • cisco cisco prime home
Full article265 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 03, 2017

The experts at Cisco have discovered a critical authentication bypass vulnerability in the Cisco Prime Home during an internal security testing.

Cisco has released a security update for CISCO Prime Home remote management and provisioning solution to fix a flaw that could be exploited to authentication bypass. The experts at Cisco have discovered the critical authentication bypass flaw during an internal security testing.

The Cisco Prime Home is a product used by Internet service providers (ISPs) to view customers’ home networks, it allows to make configuration changes and software upgrades, and could be used for the remote diagnostics.

The flaw, tracked as CVE-2017-3791, resides in the web-based user interface of the Cisco Prime Home, it can be remotely exploited by an unauthenticated attacker to bypass authentication and execute any action with administrator privileges.

“The vulnerability is due to a processing error in the role-based access control (RBAC) of URLs. An attacker could exploit this vulnerability by sending API commands via HTTP to a particular URL without prior authentication.” states the Cisco advisory. “An exploit could allow the attacker to perform any actions in Cisco Prime Home with administrator privileges.”

Cisco Prime Home

The flaw affects Cisco Prime Home versions 6.3, 6.4 and 6.5, versions 5.2 and earlier are not impacted. Cisco fixed the issue with the version 6.5.0.1, It is important to highlight the absence of a workaround.

The experts at the Cisco Product Security Incident Response Team (PSIRT) are not aware of any public announcements or exploitation of the flaw.

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – Prime Home, hacking)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/55926/hacking/cisco-prime-home-flaw.html